CVE-2015-5909
published 2015-09-18CVE-2015-5909: IDE Xcode Server in Apple Xcode before 7.0 does not properly restrict access to repository e-mail lists, which allows remote attackers to obtain potentially…
PriorityP426medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.92%
77.8th percentile
IDE Xcode Server in Apple Xcode before 7.0 does not properly restrict access to repository e-mail lists, which allows remote attackers to obtain potentially sensitive build information in opportunistic circumstances by leveraging incorrect notification delivery.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | xcode | <= 6.4 | — |
| apple | xcode | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qjv3-rm9m-w3x4: IDE Xcode Server in Apple Xcode before 7
ghsa_unreviewed·2022-05-17
CVE-2015-5909 [MEDIUM] CWE-200 GHSA-qjv3-rm9m-w3x4: IDE Xcode Server in Apple Xcode before 7
IDE Xcode Server in Apple Xcode before 7.0 does not properly restrict access to repository e-mail lists, which allows remote attackers to obtain potentially sensitive build information in opportunistic circumstances by leveraging incorrect notification delivery.
Apple
CVE-2015-5909: Xcode 7.0
vendor_apple·CVSS 5.0
CVE-2015-5909 [MEDIUM] CVE-2015-5909: Xcode 7.0
Apple Security Update: About the security content of Xcode 7.0
Product: Xcode
Version: 7.0
CVE: CVE-2015-5909
Component: CVE-ID
Impact: Multiple vulnerabilities existed in svn versions prior to 1.7.19
Description: Multiple vulnerabilities existed in svn versions prior to 1.7.19. These issues were addressed by updating svn to version 1.7.20.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-09-18
Published